Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Jack Cable

@jackhcable@mastodon.social
mastodon 4.8.0-nightly.2026-10-06
  • Open on mastodon.social

CEO & Co-founder at Corridor.

Previously: Senior Technical Advisor at CISA, TechCongress in the Senate, Krebs Stamos Group, CISA, Defense Digital Service, and Stanford.

0 Followers
0 Following
10 Posts
Joined April 26, 2022
Website:
https://cablej.io
Open post
Jack Cable @jackhcable@mastodon.social
· 17mo ago

New from Jen Easterly and me: as threats to our critical infrastructure increase, U.S. policymakers need to defend + strengthen the role of security research. This is personal for me, having received legal threats for good-faith security research.

We call on Congress to protect security researchers by codifying the DMCA security research exemption, exempt good-faith security research from the CFAA, and require software vendors to operate a VDP and publish CVEs.

https://www.lawfaremedia.org/article/advancing-secure-by-design-through-security-research

lawfaremedia.org
31
0
28
0
Open post
Jack Cable @jackhcable@mastodon.social
· 29mo ago

Today, I published in the Harvard Business Review on how business leaders of software manufacturers can prevent ransomware attacks at scale with more secure by design software.

The vast majority of ransomware attacks are enabled by a software design defect or insecure default configuration. It's up to software manufacturers to raise the tide and help secure everyone.

Read here: https://hbr.org/2024/04/preventing-ransomware-attacks-at-scale

hbr.org
13
0
14
0
Open post
Jack Cable @jackhcable@mastodon.social
· 16mo ago

I told Congress the story of how I got into hacking: winning the Hack the Air Force competition at 17, and helping start Stanford's bug bounty program as a freshman.

While we've made progress, we need to do more to normalize security research. I called on Congress to reform the Computer Fraud and Abuse Act by exempting good-faith security research.

4
0
1
0
Open post
Jack Cable @jackhcable@mastodon.social
· 20mo ago

After two incredible years, today is my last day at CISA. Immensely grateful to have been able to drive CISA's work on Secure by Design, spurring commitments from 250 software manufacturers and publishing guidance with over a dozen int'l partners.

My exit interview: https://cyberscoop.com/jack-cable-cisa-secure-by-design-exit-interview/

cyberscoop.com
6
0
0
0
Open post
Jack Cable @jackhcable@mastodon.social
· 29mo ago

Extremely excited to launch CISA's Secure by Design Pledge today — where 68 of the world's leading software manufacturers are committing to demonstrating measurable progress around secure by design in seven specific areas over the next year. This is a major step forward in our efforts to increase adoption of secure by design principles.

Read our announcement: https://www.cisa.gov/news-events/news/cisa-announces-secure-design-commitments-leading-technology-providers

cisa.gov
10
0
9
0
Open post
Jack Cable @jackhcable@mastodon.social
· 34mo ago

Have thoughts on Secure by Design? Yesterday, we announced a Request for Information on Secure by Design.

Have thoughts on eliminating classes of vulns, security education for developers, economics, AI, OT, and more? Check it out and respond (by Feb 20): https://www.federalregister.gov/documents/2023/12/20/2023-27948/request-for-information-on-shifting-the-balance-of-cybersecurity-risk-principles-and-approaches-for

federalregister.gov
10
0
8
0
Open post
Jack Cable @jackhcable@mastodon.social
· 32mo ago

Four years ago, as a computer science student at Stanford, I wrote what felt like a simple observation: I wasn’t required to take a security class, and neither were my peers.

It’s now 2024, and we’ve made little progress in educating developers. It is long overdue for academia to reconsider their role in producing a software developer workforce that writes defective software.

Read on: https://www.cisa.gov/news-events/news/we-must-consider-software-developers-key-part-cybersecurity-workforce

cisa.gov
6
0
1
0
Open post
Jack Cable @jackhcable@mastodon.social
· 34mo ago

Memory safety vulnerabilities are the most common class of vulnerabilities, and have enabled some of the most damaging cyberattacks in recent years.

Fortunately, most memory safety vulnerabilities are preventable. CISA and our partners’ guidance on memory safe roadmaps gives companies a path forward to protect their customers by eliminating this class of vulnerabilities. We urge companies to develop and publish their memory safe roadmaps and lead by example.

Read more: https://go.dhs.gov/oyE

go.dhs.gov
6
0
1
0
Open post
Jack Cable @jackhcable@mastodon.social
· 25mo ago

Excited to share new research w/ Ian Gray and Damon McCoy, where we leverage novel heuristics to identify over $700 million in previously-unreported ransomware payments. We publish our set of payments, which when combined with the Ransomwhere dataset totals over $900 million in ransomware payments — several times larger than any existing public dataset.

Read here: https://arxiv.org/abs/2408.15420
Get the data: https://github.com/cablej/showing-the-receipts

arxiv.org
2
0
2
0
Open post
Jack Cable @jackhcable@mastodon.social
· 34mo ago

Great joining @RosenzweigP@mastodon.social on the Lawfare Podcast! Tune in for some holiday listening to hear from Lauren Zabierek, Bob Lord and me on CISA's path forward on Secure by Design.

https://www.lawfaremedia.org/article/the-lawfare-podcast-three-cisa-senior-advisers-on-secure-by-design

lawfaremedia.org
3
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 08:21:51 UTC